Bug 198745

Summary: To block automatic download in sandboxed iframe
Product: WebKit Reporter: yaoxia
Component: FramesAssignee: Nobody <webkit-unassigned>
Status: NEW    
Severity: Normal CC: aestes, bfulgham, conrad_shultz, dbates, fred.wang, jberlin, webkit-bug-importer
Priority: P2 Keywords: InRadar
Version: WebKit Nightly Build   
Hardware: All   
OS: All   

yaoxia
Reported 2019-06-10 22:38:12 PDT
Preventing automatic download in sandboxed iframe should be the default as downloads can bring security vulnerabilities to the system. I'm hoping to see implementer interest. whatwg/html discussion: https://github.com/whatwg/html/issues/3236 PR: https://github.com/whatwg/html/pull/4293 WPT (already checked in): https://github.com/web-platform-tests/wpt/commit/245334dcc1695c3dbc4e1fcdbe849224234093fc
Attachments
Radar WebKit Bug Importer
Comment 1 2019-06-11 00:55:17 PDT
Note You need to log in before you can comment on or make changes to this bug.